I recently had the same issue. I could you give an example of a reject rule. This is the IP address that was used: 210.99.38.200 They tried to use the same non-existent account. Is there some exploit out there or are they just trying to get into a system that is not secured well? They have their FTP daemon running: ISA Server: extended error message : 220 WOWLiNUX Paran R2 Server ready. 530 Sorry, maxium users 10 -- try again later James